PT-2018-11032 · Dell Emc+1 · Openmanage Essentials+2

Publicado

2018-02-12

·

Atualizado

2018-03-12

·

CVE-2018-1214

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC SupportAssist Enterprise versions 1.1 through 1.2
Description The issue arises from the creation of a local Windows user account named OMEAdapterUser with a default password during the installation of Dell EMC SupportAssist Enterprise. This account remains after upgrading from version 1.1 to 1.2. Knowledge of the default password can allow unauthorized access to the management console. If SupportAssist Enterprise is installed on a server running OpenManage Essentials (OME), the OmeAdapterUser account is added to the OmeAdministrators group, potentially allowing an unauthorized person with the default password to gain access to the affected OME installation with OmeAdministrators privileges.
Recommendations For versions 1.1 through 1.2, update to version 1.2.1 to resolve the issue.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1214

Produtos afetados

Dell Emc Supportassist Enterprise
Openmanage Essentials
Windows